feat(onboarding): added signup disable for sso and post hog event on admin initalization

This commit is contained in:
Akhil Mohan
2023-11-14 13:01:07 +05:30
parent 9fbf01c19e
commit 4aacbed28b
4 changed files with 71 additions and 58 deletions
@@ -4,6 +4,7 @@ import { getServerConfig, updateServerConfig as setServerConfig } from "../../co
import { initializeDefaultOrg, issueAuthTokens } from "../../helpers"; import { initializeDefaultOrg, issueAuthTokens } from "../../helpers";
import { validateRequest } from "../../helpers/validation"; import { validateRequest } from "../../helpers/validation";
import { User } from "../../models"; import { User } from "../../models";
import { TelemetryService } from "../../services";
import { BadRequestError, UnauthorizedRequestError } from "../../utils/errors"; import { BadRequestError, UnauthorizedRequestError } from "../../utils/errors";
import * as reqValidator from "../../validation/admin"; import * as reqValidator from "../../validation/admin";
@@ -71,6 +72,18 @@ export const adminSignUp = async (req: Request, res: Response) => {
const token = tokens.token; const token = tokens.token;
const postHogClient = await TelemetryService.getPostHogClient();
if (postHogClient) {
postHogClient.capture({
event: "admin initialization",
properties: {
email: user.email,
lastName,
firstName
}
});
}
// store (refresh) token in httpOnly cookie // store (refresh) token in httpOnly cookie
res.cookie("jid", tokens.refreshToken, { res.cookie("jid", tokens.refreshToken, {
httpOnly: true, httpOnly: true,
@@ -5,7 +5,6 @@ import { createToken } from "../../helpers/auth";
import { BadRequestError } from "../../utils/errors"; import { BadRequestError } from "../../utils/errors";
import { import {
getAuthSecret, getAuthSecret,
getInviteOnlySignup,
getJwtSignupLifetime, getJwtSignupLifetime,
getSmtpConfigured getSmtpConfigured
} from "../../config"; } from "../../config";
@@ -68,7 +67,6 @@ export const verifyEmailSignup = async (req: Request, res: Response) => {
}); });
} }
if (await getInviteOnlySignup()) {
// Only one user can create an account without being invited. The rest need to be invited in order to make an account // Only one user can create an account without being invited. The rest need to be invited in order to make an account
const userCount = await User.countDocuments({}); const userCount = await User.countDocuments({});
if (userCount != 0) { if (userCount != 0) {
@@ -76,7 +74,6 @@ export const verifyEmailSignup = async (req: Request, res: Response) => {
message: "New user sign ups are not allowed at this time. You must be invited to sign up." message: "New user sign ups are not allowed at this time. You must be invited to sign up."
}); });
} }
}
// verify email // verify email
if (await getSmtpConfigured()) { if (await getSmtpConfigured()) {
+12 -9
View File
@@ -1,10 +1,8 @@
import { import { AuthMethod, User } from "../../../models";
AuthMethod,
User
} from "../../../models";
import { createToken } from "../../../helpers/auth"; import { createToken } from "../../../helpers/auth";
import { AuthTokenType } from "../../../variables"; import { AuthTokenType } from "../../../variables";
import { getAuthSecret, getJwtProviderAuthLifetime} from "../../../config"; import { getAuthSecret, getJwtProviderAuthLifetime } from "../../../config";
import { getServerConfig } from "../../../config/serverConfig";
interface SSOUserTokenFlowParams { interface SSOUserTokenFlowParams {
email: string; email: string;
@@ -25,6 +23,9 @@ export const handleSSOUserTokenFlow = async ({
email email
}).select("+publicKey"); }).select("+publicKey");
const serverCfg = getServerConfig();
if (!user && !serverCfg.allowSignUp) throw new Error("User signup disabled");
if (!user) { if (!user) {
user = await new User({ user = await new User({
email, email,
@@ -50,13 +51,15 @@ export const handleSSOUserTokenFlow = async ({
authMethod, authMethod,
isUserCompleted, isUserCompleted,
isLinkingRequired, isLinkingRequired,
...(callbackPort ? { ...(callbackPort
? {
callbackPort callbackPort
} : {}) }
: {})
}, },
expiresIn: await getJwtProviderAuthLifetime(), expiresIn: await getJwtProviderAuthLifetime(),
secret: await getAuthSecret(), secret: await getAuthSecret()
}); });
return { isUserCompleted, providerAuthToken }; return { isUserCompleted, providerAuthToken };
} };
@@ -31,9 +31,9 @@ export const AdminDashboardPage = () => {
return ( return (
<div className="container mx-auto max-w-7xl pb-12 text-white dark:[color-scheme:dark]"> <div className="container mx-auto max-w-7xl pb-12 text-white dark:[color-scheme:dark]">
<div className="mb-8"> <div className="mb-8">
<div className="mx-4 mb-4 mt-6 flex flex-col items-start justify-between px-2 text-xl"> <div className="mb-4 mt-6 flex flex-col items-start justify-between text-xl">
<h1 className="text-3xl font-semibold">Admin Dashboard</h1> <h1 className="text-3xl font-semibold">Admin Dashboard</h1>
<p className="text-base text-bunker-300">Manage your Infisical.</p> <p className="text-base text-bunker-300">Manage your Infisical</p>
</div> </div>
</div> </div>
{isUserLoading || isNotAllowed ? ( {isUserLoading || isNotAllowed ? (